Work Practices of Cyber Security Professionals

Valdis.Kletnieks at vt.edu Valdis.Kletnieks at vt.edu
Tue Feb 18 14:28:55 UTC 2014


On Mon, 17 Feb 2014 15:27:25 +0000, Muhammad Adnan said:

> I am a university researcher who is investigating the development of new,
> usable tools that will improve the work practices of cyber security
> professionals. As a first step to achieve this goal, I am undertaking a
> survey to gain an in-depth understanding of the day-to-day activities of
> cyber security professionals. The targeted participants for this survey are
> those who perform security related activities as a part of their job (e.g.
> security analysts, network administrators, penetration testers).

Several comments:

1) If you're including network admins, you should also make sure to
get system admins (though you'll be more successful asking elsewhere for those).

2) Having worn at least a partial hat of all those along my careeer, I'm
curious what sort of tools will improve work practices for all the groups
concerned.  Probably the only place you'll find much overlap is in record
keeping - but even there the record keeping that a sysadmin needs to do for
changelogging their boxes is fairly different from what security analysts
working an incident and pen testers engaged in a test will need.  There's
also the problem that many sites have their change logging integrated into
their version control system or other workflow software already...

Good luck!
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 848 bytes
Desc: not available
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20140218/6b414a5e/attachment.sig>


More information about the NANOG mailing list